Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-16928

86
FAUCET Score

CVE-2019-16928 is a critical heap-based buffer overflow vulnerability in Exim versions 4.92 through 4.92.2, affecting distributions like Canonical, Debian, and Fedora. This flaw allows unauthenticated remote attackers to achieve remote code execution by sending a specially crafted, long EHLO command. With a CVSS score of 9.8, it presents a low-complexity attack vector with high impact on confidentiality, integrity, and availability. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered significant community discussion and media coverage, despite a lack of public exploit tools like Metasploit or ExploitDB entries.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.92, <= 4.92.2CPE matchmatch criteria
cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:*
19.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
29CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
30CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
41.59%
Probability of exploitation in next 30 days
EPSS Percentile
98.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Added to KEV · Mar 3, 2022
This CVE's current EPSS score of 0.4159 is in the 96th percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (6)

boschvendor investigatingvia llm_extracted
citrix_adcvendor investigatingvia llm_extracted
View patch
esetvendor investigatingvia llm_extracted
View patch
giteavendor investigatingvia llm_extracted
View patch
googlevendor investigatingvia llm_extracted
rocketchatvendor investigatingvia llm_extracted

Vendor Advisories (7)

giteallm-gitea-2cef4b94b4594545
Dec 17, 2025
redhatCVE-2019-16928Critical

exim: remotely triggerable buffer overflow in string_vformat()

Sep 27, 2019
googlellm-google-8cde54abfa37ee1b

Security Advisory for CVE-2019-16928

esetllm-eset-f4d62a76d409a43d
citrix_adcllm-citrix_adc-d8877b01cd2eceb6
boschllm-bosch-7982536e978c4d70

Security Advisory for CVE-2019-16928

rocketchatllm-rocketchat-2a435a9741afbb96

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
bugs.exim.org / show_bug.cgi
Issue TrackingPatchVendor Advisory
git.exim.org / exim.git/commit/478effbfd9c3cc5a627fc671d4bf94d13670d65f
Patch
lists.exim.org / lurker/message/20190927.032457.c1044d4c.en.html
Vendor Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/EED7HM3MFIBAP5OIMJAFJ35JAJABTVSC
Release Notes
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/T3TJW4HPYH3O5HZCWGD6NSHTEBTTAPDC
Release Notes
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/UY6HPRW7MR3KBQ5JFHH6OXM7YCZBJCOB
Release Notes
seclists.org / bugtraq/2019/Sep/60
Mailing ListThird Party Advisory
security.gentoo.org / glsa/202003-47
Third Party Advisory
usn.ubuntu.com / 4141-1
Third Party Advisory
debian.org / security/2019/dsa-4536
Third Party Advisory
openwall.com / lists/oss-security/2019/09/28/1
ExploitMailing ListMitigationThird Party Advisory
openwall.com / lists/oss-security/2019/09/28/2
ExploitMailing ListThird Party Advisory
openwall.com / lists/oss-security/2019/09/28/3
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2019/09/28/4
Mailing ListThird Party Advisory